lebesgue-measure
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions facilitate the ingestion of untrusted mathematical expressions which are then executed as shell command arguments.
- Ingestion points: Mathematical expressions are passed as string arguments to
scripts/sympy_compute.pyandscripts/z3_solve.pywithin theTool Commandssection ofSKILL.md. - Boundary markers: No delimiters or explicit instructions to ignore embedded control characters are provided, potentially allowing an attacker to inject shell commands via the expression strings.
- Capability inventory: The skill utilizes the
Bashtool to run commands viauv run, providing a mechanism for command execution. - Sanitization: There is no evidence of input validation or sanitization to ensure the strings passed to the Python scripts are strictly mathematical and do not contain malicious shell sequences.
Audit Metadata